HomeRisk ManagementsUS Defense Contractors Acknowledge Potential Inaccuracy in Their CMMC Scores

US Defense Contractors Acknowledge Potential Inaccuracy in Their CMMC Scores

Published on

spot_img

Concerns Rise Among Defense Contractors Over Cybersecurity Self-Assessment Accuracy

In a recent development following the Pentagon’s decision to pause third-party audit mandates for the U.S. defense industrial base (DIB), many contractors have expressed a lack of trust in their own cybersecurity scores. This concern stems from uncertainties regarding the effectiveness of self-reported cybersecurity metrics amidst a challenging compliance environment.

A new study, the 2026 State of the DIB Report, published by CyberSheath on August 20, presents a complex picture. While the average Supplier Performance Risk System (SPRS) score has surged to a five-year high of +51—an increase from +33 in 2025 and the first positive score ever recorded—the confidence in the accuracy of these scores has notably plummeted. The SPRS framework serves as a self-assessment tool for U.S. defense contractors to evaluate their cybersecurity maturity in relation to the Cybersecurity Maturity Model Certification (CMMC).

The CMMC program aims to elevate cyber hygiene among U.S. defense contractors and subcontractors that manage federal contract information (FCI) and controlled unclassified information (CUI) for the Department of Defense (DoD). Complying with the Defense Federal Acquisition Regulation Supplement (DFARS) remains essential for contractors looking to secure a DoD contract, transforming CMMC requirements into legally binding obligations.

Through the SPRS framework, DIB contractors and subcontractors engage in self-evaluations based on 110 security controls delineated in NIST SP 800-171, a widely recognized standard released by the U.S. National Institute of Standards and Technology. A perfect score in this assessment is 110. While Phase I of the CMMC program solely mandates self-reporting, Phase II was poised to introduce independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs). However, this phase was postponed in July 2026 by the Trump administration.

Despite the record-high SPRS scores outlined in the CyberSheath study, a troubling trend has emerged regarding contractors’ confidence in these self-assessments. According to the survey conducted by Merrill Research, only 65% of contractors reported feeling "extremely" or "very" confident that their scores were accurate, a sharp decrease from 89% in the previous year and 94% in 2024. David M. Schneer, CEO of Merrill Research, characterized this disparity as “the most striking finding this year.” He emphasized that, while contractors are revealing higher SPRS scores and an increased adoption of vital cybersecurity capabilities, a significant drop in confidence regarding the accuracy of these scores raises concerns over how to genuinely measure cybersecurity progress.

Additionally, the survey found that only 1% of contractors believe they are fully prepared for CMMC certification. This statistic underscores the ongoing struggle within the DIB to meet or even understand the compliance requirements.

While financial constraints do not appear to be the primary barrier to compliance—53% of respondents indicated that their budgets felt “just right,” and 24% considered them more than sufficient—challenges related to implementing effective cybersecurity measures persist. The average budget for DFARS compliance has increased to approximately $155,204 annually. The CyberSheath report noted that the actual obstacle for the DIB transcends monetary expenditure; it lies in effectively translating investments into sustainable and verifiable security practices.

Interestingly, the study indicated that despite over half (52%) of DIB members fearing they might lose contracts due to non-compliance, a resounding 90% still favor legal mandates for minimum cybersecurity standards for both defense contractors and subcontractors. Furthermore, while a substantial majority (77%) believe DFARS compliance genuinely enhances national security, there is a palpable demand for reassessment of how these regulations are implemented. Approximately 74% of contractors are calling for simplified implementation processes, and 70% seek greater vendor options to assist in compliance efforts.

Emil Sayegh, the CEO of CyberSheath, addressed the current landscape by stressing that most DIB contractors consist of manufacturers, engineers, and specialized businesses whose primary goal is to support national defense, not to become cybersecurity professionals. He urged the federal administration to revamp the CMMC program to facilitate easier and more effective cybersecurity measures while ensuring that objective and verifiable assurances of defense are maintained.

Sayegh reiterated that as CMMC evolves, core principles of meaningful verification and accountability must remain central, ensuring that reported compliance accurately reflects operational cybersecurity states.

The 2026 State of the DIB Report derives insights from a survey encompassing 302 U.S. defense contractors, including 195 prime contractors, 118 subcontractors, and 11 organizations recognizing as both. The data highlights the urgent need for systemic changes to bolster both confidence and security among contractors within the defense sector.

Source link

Latest articles

Black Hat 2026 – The Supply-Chain Trust Series

Black Hat 2026: Exploring the Supply-Chain Trust Dilemma By Dr. Arun Lakhotia The forthcoming Black Hat...

Breach Roundup: Grandoreiro Returns – GovInfoSecurity

Cybersecurity Breaches and Ransomware Threats: A Weekly Overview In a rapidly evolving digital landscape fraught...

MacSync Stealer Leverages Over 30 Rotating Domains to Harvest macOS Credentials and Exfiltrate Data

MacSync Stealer Expands Its macOS Theft Operation through 30+ Rotating Domains In a concerning development...

Citrix Releases Critical Security Updates for NetScaler Devices

Citrix Issues Critical Security Alerts Amid Potential Exploitation Risks In a recent advisory, cybersecurity experts...

More like this

Black Hat 2026 – The Supply-Chain Trust Series

Black Hat 2026: Exploring the Supply-Chain Trust Dilemma By Dr. Arun Lakhotia The forthcoming Black Hat...

Breach Roundup: Grandoreiro Returns – GovInfoSecurity

Cybersecurity Breaches and Ransomware Threats: A Weekly Overview In a rapidly evolving digital landscape fraught...

MacSync Stealer Leverages Over 30 Rotating Domains to Harvest macOS Credentials and Exfiltrate Data

MacSync Stealer Expands Its macOS Theft Operation through 30+ Rotating Domains In a concerning development...